CVE-2026-1242
- EPSS 0.18%
- Veröffentlicht 19.09.2026 07:43:14
- Zuletzt bearbeitet 21.09.2026 13:33:33
The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes ...
CVE-2025-62026
- EPSS 0.26%
- Veröffentlicht 22.10.2025 14:32:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
Insertion of Sensitive Information Into Sent Data vulnerability in Blockspare Blockspare blockspare allows Retrieve Embedded Sensitive Data.This issue affects Blockspare: from n/a through <= 3.2.13.2.
CVE-2025-47495
- EPSS 0.25%
- Veröffentlicht 07.05.2025 14:19:54
- Zuletzt bearbeitet 23.04.2026 15:30:20
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blockspare Blockspare blockspare allows Stored XSS.This issue affects Blockspare: from n/a through <= 3.2.9.
CVE-2024-47363
- EPSS 0.25%
- Veröffentlicht 06.10.2024 10:15:04
- Zuletzt bearbeitet 23.04.2026 15:19:14
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blockspare Blockspare blockspare allows Stored XSS.This issue affects Blockspare: from n/a through <= 3.2.4.
CVE-2024-8325
- EPSS 0.26%
- Veröffentlicht 04.09.2024 06:15:17
- Zuletzt bearbeitet 07.10.2024 12:37:58
The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s...
CVE-2024-43164
- EPSS 0.26%
- Veröffentlicht 12.08.2024 22:15:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Blockspare allows Stored XSS.This issue affects Blockspare: from n/a through 3.2.0.